Live data from Hacker News

Japan facing credit card number shortage

mainichi.jp

211–220 of 360 posts

Re: Japan facing credit card number shortage

#211

Earlier quoted context omitted.

Except that 3D Secure is opt-in by the merchant. All you need to do is find a web store that is more than 2 years old and you can use stolen/skimmed cards all day long.

... at the risk of the store. The card holder just goes to the bank, says "I didn't do those transactions!" and gets all money back.

That's how it works for all credit card fraud. But do they treat 3D Secure transactions any differently?

Re: Japan facing credit card number shortage

#212

Earlier quoted context omitted.

As an adult who tries to remember the NATO phonetic alphabet but can't because I only use it once per month, I don't make up words "for fun" or "to be cute". I do it because I can't remember the NATO word. Compared to just saying the letters, the words I choose certainly do reduce ambiguity, even if using the NATO alphabet would go even further.

Some good advice I got from a HAM was to read license plates in your head using the NATO alphabet. Their letters are mostly random so you tend to see each letter at roughly the same frequency and it can be done daily without taking away time from your schedule. Being random also prevents you from just remembering the order of the words and actually associating them with their respective letters. After doing that for…

[deleted]

Re: Japan facing credit card number shortage

#213
post #164

Earlier quoted context omitted.

The problem isn’t the tools. It’s that there is no such thing as an operable PKI. The best PKI (by far) is the CA system, and the CA system is not a good PKI. It has so many holes, and the PKI evangelists don’t like it anyway, because it uses trusted authorities. The only other examples of remotely useful PKIs in existence are things like Signal/WhatsApp... and those are even worse PKIs, because TOFU PKIs are in prac…

The US DoD has a perfectly useful and operable PKI infrastructure https://www.cac.mil/Common-Access-Card/CAC-Security/

Haha, the “CAC” as we liked to call it.

It is a pretty secure system I think, but government procedures make it a pain to work with.

Re: Japan facing credit card number shortage

#214

Earlier quoted context omitted.

It only works if you have a chip inside, like Yubikey and other HSMs do. You can't do crypto with dumb block storage. But if you have a chip you should absolutely do _something_ smarter than storing and reciting the number verbatim.

Virtually every country other than the United States uses a cryptographic NFC and/or chip and pin system for in-person credit/debit transactions. In most countries, the card number is only used for online and phone transactions. There's probably no way to do better than this without abandoning cards entirely in favor of some kind of device (or app) that has enough of a user interface to do a human-readable challenge…

Practically all online VISA/MC card transactions at domestic online stores here in Finland are verified by 2-factor authentication using bank credentials (3dsecure etc.), it has been this way for over 10 years now.

Re: Japan facing credit card number shortage

#215

Earlier quoted context omitted.

then those merchants should use the widely popular 3d secure system, which lets you enter a pin. by using it, they are protected from reversals by the terms of service. so a system that prevents them losing a gazillion dollars is available, and they opt to instead lose the gazillion dollars. it's their fault, and they should lose that money. we don't need to tell them anything -we just need to point and laugh.

And then see customers complaining about the annoying extra steps. 3D Secure affects conversion rates adversely which means customers are generally happier without it and don't mind the fraud risk (as is consistent with the rest of this discussion on the thread).

Really? In Russia I haven’t seen a single store without 3D Secure for a loooong time. And they are doing quite fine. Maybe it’s just that US customers are lazy?

Re: Japan facing credit card number shortage

#216
post #151

Earlier quoted context omitted.

That’s very US centric. In every other place except America, credit card issuers mandate the use EMV’s and pin codes.

I think most us cards have chips, but no pins. It’s bizarre.

You can't skim the chip but you can trivially intercept the PIN.

Re: Japan facing credit card number shortage

#217

Earlier quoted context omitted.

That only works because it’s hidden from the user, and can only work on highly regulated approved devices. Try giving a user a private key for making CNP transactions, and all you will have achieved is replicating the user experience of bitcoin.

> Try giving a user a private key for making CNP transactions, I have that! > and all you will have achieved is replicating the user experience of bitcoin. I've never used bitcoin or any other cryptocurrency. What's the user experience like?

You just have the target wallet address and the "send" button, zero bullshit, like paper money.

Re: Japan facing credit card number shortage

#218
post #185
post #176

Earlier quoted context omitted.

What the OP said was that even with a 6 digit BIN and 1 digit check, you have 9 digits available per BIN. For example, Mastercards start in the range 51 to 55. That leaves 4 digits of the 6 digit BIN to allocate to MC issuers. So that's a total of 50K issuers of MC world wide, then each of those issuers can have 1 billion cards. So each issuer of a MC in Japan can issue a card to each member of the population and onl…

> an eight of their allocated range Assuming your calculations are correct, this means an issuer can only emit 8 cards in average to the total population. Cards have an expiration, people lose them, break them, they change and come back to banks. For the main issuers it’s not ridiculous to have to issue 20 or 30 cards per account to a user in their lifetime. Then people have multiple accounts (e.g. my mortgage was on…

[deleted]

Re: Japan facing credit card number shortage

#219
post #187

Earlier quoted context omitted.

It's called 3D Secure and requires a PIN to verify transaction(typically with SMS), or a security device provided by bank.

Except that 3D Secure is opt-in by the merchant. All you need to do is find a web store that is more than 2 years old and you can use stolen/skimmed cards all day long.

My primary card declines all non 3D Secure internet purchases unless I click the scary sounding "Open card to all internet purchases for 60 minutes" button in the bank app.
Post reply on HN